[Bug 930430] Re: lxc-ls requires root access after deploying an LXC instance

2012-08-13 Thread Andreas Hasenack
Hi Jamie, I started seeing this with juju 0.5.1+bzr563-0juju2~precise1, to which I recently upgraded. With 0.5+bzr531-0ubuntu1.2 (also in precise) it works. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.la

[Bug 1673411] Re: config-drive support is broken

2017-04-13 Thread Andreas Hasenack
Verified on yakkety with a yakkety lxd container and the provided instructions: *** 0.7.9-90-g61eb03fe-0ubuntu1~16.10.1 500 500 http://archive.ubuntu.com/ubuntu yakkety-proposed/main amd64 Packages Created a config-drive and verified the result.json file: $ lxc file pull $name/run/clo

[Bug 1673411] Re: config-drive support is broken

2017-04-13 Thread Andreas Hasenack
Verified on xenial with a xenial lxd container and the provided instructions: Version table: *** 0.7.9-90-g61eb03fe-0ubuntu1~16.04.1 500 500 http://archive.ubuntu.com/ubuntu xenial-proposed/main amd64 Packages $ lxc exec x1-fixed cat /run/cloud-init/result.json { "v1": { "datasource

[Bug 1673411] Re: config-drive support is broken

2017-04-13 Thread Andreas Hasenack
** Tags removed: verification-needed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cloud-init in Ubuntu. https://bugs.launchpad.net/bugs/1673411 Title: config-drive support is broken To manage notifications about this bug go to: h

[Bug 1674946] Re: cloud-init fails with "Unknown network_data link type: dvs"

2017-04-13 Thread Andreas Hasenack
Also verified it with xenial and a config-drive that had "type": "dvs" in openstack/latest/network_data.json using the proposed package: root@x1-fixed:~# apt-cache policy cloud-init cloud-init: Installed: 0.7.9-90-g61eb03fe-0ubuntu1~16.04.1 Candidate: 0.7.9-90-g61eb03fe-0ubuntu1~16.04.1 Vers

[Bug 1674946] Re: cloud-init fails with "Unknown network_data link type: dvs"

2017-04-13 Thread Andreas Hasenack
Using the package from yakkety-proposed in a yakkety LXD container: $ lxc exec y1-proposed -- /bin/bash root@y1-proposed:~# apt-cache policy cloud-init cloud-init: Installed: 0.7.9-90-g61eb03fe-0ubuntu1~16.10.1 Candidate: 0.7.9-90-g61eb03fe-0ubuntu1~16.10.1 Version table: *** 0.7.9-90-g61eb

[Bug 1570325] Re: RFE: chpasswd in cloud-init should support hashed passwords

2017-04-17 Thread Andreas Hasenack
Tests passed for xenial according to the instructions (see attached output). ** Attachment added: "lp-1570325-xenial.txt" https://bugs.launchpad.net/cloud-init/+bug/1570325/+attachment/4863558/+files/lp-1570325-xenial.txt -- You received this bug notification because you are a member of Ubun

[Bug 1570325] Re: RFE: chpasswd in cloud-init should support hashed passwords

2017-04-17 Thread Andreas Hasenack
Tests passed for yakkety according to the instructions (see attached output). ** Attachment added: "lp-1570325-yakkety.txt" https://bugs.launchpad.net/cloud-init/+bug/1570325/+attachment/4863559/+files/lp-1570325-yakkety.txt -- You received this bug notification because you are a member of

[Bug 1570325] Re: RFE: chpasswd in cloud-init should support hashed passwords

2017-04-17 Thread Andreas Hasenack
Also launched a yakkety lxd with the attached user-data file, and it correctly changed the user's password to the provided hash. lxc launch b03fe-yakkety-proposed y1-proposed "--config=user.user- data=$(cat cloud-init.yaml)" ** Attachment added: "cloud-init.yaml" https://bugs.launchpad.net/cl

[Bug 1570325] Re: RFE: chpasswd in cloud-init should support hashed passwords

2017-04-17 Thread Andreas Hasenack
Also launched a xenial lxd container with the same user-data file as in the previous comment and it correctly changed the "tom" user's password to the provided hash. lxc launch b03fe-xenial-proposed x1-proposed "--config=user.user- data=$(cat cloud-init.yaml)" ** Tags removed: verification-needed

[Bug 1677710] Re: ds-identify does not find maas datasource

2017-04-17 Thread Andreas Hasenack
** Description changed: === Begin SRU Template === [Impact] On systems deployed with MAAS xenial and yakkety systems would put a warning on the login screen stating that the datasource was not found. - [Test Case] The full test case involves  * deploying through MAAS  * enablin

[Bug 1677710] Re: ds-identify does not find maas datasource

2017-04-17 Thread Andreas Hasenack
I'm having difficulties in reproducing the problematic case. I added this to /etc/maas/preseeds/curtin_userdata: (...) system_upgrade: enabled: True late_commands: (...) Deploying yakkety without -proposed, I don't see any error regarding not finding a datasource, either in the logs, or in the

[Bug 1677710] Re: ds-identify does not find maas datasource

2017-04-18 Thread Andreas Hasenack
It's hard to reproduce the same error condition, as this happened during the development of a new feature (deploying ubuntu-core via MAAS). The closest I could get to it after some help from Ryan Harper was to run ds-identify on a normally deployed MAAS node with the current cloud-init and the prop

[Bug 1677710] Re: ds-identify does not find maas datasource

2017-04-18 Thread Andreas Hasenack
For xenial: With the current cloud-init, where the problem appears: *** 0.7.9-48-g1c795b9-0ubuntu1~16.04.1 500 500 http://br.archive.ubuntu.com/ubuntu xenial-updates/main amd64 Packages # remove generated files root@15-89:/run/cloud-init# rm cloud.cfg ds-identify.log # cloud-init confi

[Bug 1602813] Re: openvpn-auth-ldap causing segfault on network timeout

2017-04-19 Thread Andreas Hasenack
** Changed in: openvpn-auth-ldap (Ubuntu) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: openvpn-auth-ldap (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed

[Bug 1674946] Re: cloud-init fails with "Unknown network_data link type: dvs"

2017-04-20 Thread Andreas Hasenack
I'll try rebooting a xenial node that has the updated cloud-init package and see what happens. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cloud-init in Ubuntu. https://bugs.launchpad.net/bugs/1674946 Title: cloud-init fails with

[Bug 1674946] Re: cloud-init fails with "Unknown network_data link type: dvs"

2017-04-20 Thread Andreas Hasenack
@ashish-kumar-gupta can you please attach your /var/log/cloud-init*.log from this attempt? Also please the output of: sudo ls -lah /var/lib/cloud/instance/ /var/lib/cloud/data/ /run/cloud-init/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscri

[Bug 1674946] Re: cloud-init fails with "Unknown network_data link type: dvs"

2017-04-20 Thread Andreas Hasenack
** Tags removed: verification-done-xenial ** Tags added: verification-needed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cloud-init in Ubuntu. https://bugs.launchpad.net/bugs/1674946 Title: cloud-init fails with "Unknown network_

[Bug 1674946] Re: cloud-init fails with "Unknown network_data link type: dvs"

2017-04-20 Thread Andreas Hasenack
@ashish-kumar-gupta you seem to be hitting this bug: https://launchpad.net/bugs/1531880 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cloud-init in Ubuntu. https://bugs.launchpad.net/bugs/1674946 Title: cloud-init fails with "Unkno

[Bug 1674946] Re: cloud-init fails with "Unknown network_data link type: dvs"

2017-04-20 Thread Andreas Hasenack
For the record, I did reboot a maas node that had the config-drive network configuration to use "dvs" and it didn't fail. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to cloud-init in Ubuntu. https://bugs.launchpad.net/bugs/1674946 Tit

[Bug 1602813] Re: openvpn-auth-ldap causing segfault on network timeout

2017-04-24 Thread Andreas Hasenack
** Bug watch added: Debian Bug tracker #680166 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=680166 ** Also affects: openvpn-auth-ldap (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=680166 Importance: Unknown Status: Unknown ** No longer affects: openvpn (Ubuntu)

[Bug 1602813] Re: openvpn-auth-ldap causing segfault on network timeout

2017-04-24 Thread Andreas Hasenack
Removing the debian bug task, the linked bug is similar but it requires an additional fix on top the one provided here. ** No longer affects: openvpn-auth-ldap (Debian) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. ht

[Bug 1602813] Re: openvpn-auth-ldap causing segfault on network timeout

2017-04-24 Thread Andreas Hasenack
** Bug watch added: Debian Bug tracker #861107 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=861107 ** Also affects: openvpn-auth-ldap (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=861107 Importance: Unknown Status: Unknown -- You received this bug notification

[Bug 1602813] Re: openvpn-auth-ldap causing segfault on network timeout

2017-04-24 Thread Andreas Hasenack
debdiff for artful ** Patch added: "lp1602813.debdiff" https://bugs.launchpad.net/debian/+source/openvpn-auth-ldap/+bug/1602813/+attachment/4867421/+files/lp1602813.debdiff -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug re

[Bug 1188475] Re: ldap group doesn't work

2017-04-24 Thread Andreas Hasenack
User filed upstream bug at https://github.com/cyrusimap/cyrus- sasl/issues/427 ** Bug watch added: github.com/cyrusimap/cyrus-sasl/issues #427 https://github.com/cyrusimap/cyrus-sasl/issues/427 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subs

[Bug 1188475] Re: ldap group doesn't work

2017-04-24 Thread Andreas Hasenack
Can you share your saslauthd configuration, and portions of your DIT showing how the users and groups are organised? At first glance, it feels correct to be using the user's DN to check for group membership. I would certainly expect to be able to tell which groups I belong to without having to res

[Bug 1669193] Re: feature request - json stats output

2017-04-26 Thread Andreas Hasenack
** Bug watch added: Debian Bug tracker #856905 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856905 ** Also affects: bind9 (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856905 Importance: Unknown Status: Unknown -- You received this bug notification because you

[Bug 1669193] Re: feature request - json stats output

2017-04-26 Thread Andreas Hasenack
I also updated the debian bug. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1669193 Title: feature request - json stats output To manage notifications about this bug go to: https://

[Bug 1669193] Re: feature request - json stats output

2017-04-26 Thread Andreas Hasenack
Simple debdiff to enable json support for the statistics. To test, add this to /etc/bind/named.conf.local and restart bind: statistics-channels { inet * port allow { 127.0.0.1; }; }; (replace 127.0.0.1 with "any" if you prefer) Then access the endpoint: wget http://localhost:/json

[Bug 715765] Re: Can't change kerberos password

2017-05-01 Thread Andreas Hasenack
I tried with xenial (krb5 1.13.2+dfsg-5ubuntu2) and precise (krb5 1.10+dfsg~beta1-2ubuntu0.7) and kpasswd worked in both cases when having the principal created with the preauth flag (it was hinted this could have been the problem). This is on precise (1.10): kadmin.local: addprinc +requires_prea

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-03 Thread Andreas Hasenack
** Changed in: krb5 (Ubuntu Zesty) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: krb5 (Ubuntu Zesty) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-03 Thread Andreas Hasenack
This launchpad bug was "overloaded" and is talking about 3 issues: a) kinit fails for OTP user when using kdc discovery via DNS - upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8554 - debian: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856307 - debian patch: 0013-Fix-udp_preference

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-03 Thread Andreas Hasenack
https://bugs.launchpad.net/ubuntu/+source/krb5/+bug/1688121 filed for (b) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1683237 Title: krb5-user: kinit fails for OTP user when using k

[Bug 1688121] [NEW] KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-03 Thread Andreas Hasenack
nues) (8) and the whole tcp handshake happens with the correct IP addresses and the exchange happens and we get the ticket, but not before kinit repeats the request with PREAUTH and UDP again. That's why it takes 2 seconds in the end :) ** Affects: krb5 (Ubuntu) Importance: Un

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-04 Thread Andreas Hasenack
** Bug watch added: krbdev.mit.edu/rt/ #8530 http://krbdev.mit.edu/rt/Ticket/Display.html?id=8530 ** Also affects: krb5 (Debian) via http://krbdev.mit.edu/rt/Ticket/Display.html?id=8530 Importance: Unknown Status: Unknown -- You received this bug notification because you are a me

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-04 Thread Andreas Hasenack
With the fix applied, we get this: $ time kinit -k -t /home/ubuntu/ubuntu.keytab ubuntu real0m0.023s And the traffic happens all in UDP, since kinit got the "PREAUTH required" response (because now it came from the correct source IP) and just issued the updated request right away: 1 0.

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-04 Thread Andreas Hasenack
** Changed in: krb5 (Ubuntu Zesty) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: krb5 (Ubuntu) Assignee: Andreas Hasenack (ahasenack) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscri

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-04 Thread Andreas Hasenack
** Changed in: krb5 (Ubuntu Zesty) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs/1688121 Title: KDC/kadmind explicit wildcard listener addresses do n

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-04 Thread Andreas Hasenack
** Description changed: This is fixed in artful in krb5 1.15-2 - upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8530 - debian: conflated into https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860767 - debian patch in artful's krb5: 0012-Use-pktinfo-for-explicit-UDP-wildcard

[Bug 1688310] [NEW] KDC/kadmind may fail to start on IPv4-only systems

2017-05-04 Thread Andreas Hasenack
ed setting up a UDP socket (for ::.750) ** Affects: krb5 (Ubuntu) Importance: Undecided Assignee: Andreas Hasenack (ahasenack) Status: In Progress -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-04 Thread Andreas Hasenack
https://bugs.launchpad.net/ubuntu/+source/krb5/+bug/1688310 filed for (c) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1683237 Title: krb5-user: kinit fails for OTP user when using k

[Bug 1688310] Re: KDC/kadmind may fail to start on IPv4-only systems

2017-05-04 Thread Andreas Hasenack
** Changed in: krb5 (Ubuntu) Assignee: Andreas Hasenack (ahasenack) => (unassigned) ** Changed in: krb5 (Ubuntu) Status: In Progress => Fix Released ** Changed in: krb5 (Ubuntu Zesty) Status: New => In Progress ** Changed in: krb5 (Ubuntu Zesty) Assignee: (u

[Bug 1688310] Re: KDC/kadmind may fail to start on IPv4-only systems

2017-05-04 Thread Andreas Hasenack
** Bug watch added: Debian Bug tracker #860767 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860767 ** Also affects: krb5 (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860767 Importance: Unknown Status: Unknown -- You received this bug notification because you

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-04 Thread Andreas Hasenack
Ok, I got a simpler test case for (a) that doesn't involve setting up FreeIPA, PKINIT or OTP. I'll update the bug description about it tomorrow and then proceed with the SRU paperwork and actual packages. -- You received this bug notification because you are a member of Ubuntu Server Team, which

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-05 Thread Andreas Hasenack
** Description changed: + This is fixed in krb5 1.15-2 in artful + + Upstream bug : http://krbdev.mit.edu/rt/Ticket/Display.html?id=8554 + Debian bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856307 + Debian patch in 1.15-2 in artful: 0013-Fix-udp_preference_limit-with-SRV-records.patch

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-05 Thread Andreas Hasenack
** Description changed: This is fixed in krb5 1.15-2 in artful Upstream bug : http://krbdev.mit.edu/rt/Ticket/Display.html?id=8554 Debian bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856307 Debian patch in 1.15-2 in artful: 0013-Fix-udp_preference_limit-with-SRV-records.patch

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-05 Thread Andreas Hasenack
** Description changed: This is fixed in krb5 1.15-2 in artful Upstream bug : http://krbdev.mit.edu/rt/Ticket/Display.html?id=8554 Debian bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856307 Debian patch in 1.15-2 in artful: 0013-Fix-udp_preference_limit-with-SRV-records.patch

[Bug 1683237] Re: krb5-user: kinit fails for OTP user when using kdc discovery via DNS

2017-05-05 Thread Andreas Hasenack
** Description changed: This is fixed in krb5 1.15-2 in artful Upstream bug : http://krbdev.mit.edu/rt/Ticket/Display.html?id=8554 Debian bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856307 Debian patch in 1.15-2 in artful: 0013-Fix-udp_preference_limit-with-SRV-records.patch

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-05 Thread Andreas Hasenack
** Description changed: This is fixed in artful in krb5 1.15-2 - upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8530 - debian: conflated into https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860767 - debian patch in artful's krb5: 0012-Use-pktinfo-for-explicit-UDP-wildcard

[Bug 1688310] Re: KDC/kadmind may fail to start on IPv4-only systems

2017-05-05 Thread Andreas Hasenack
** Description changed: This is fixed in artful in krb5 1.15-2 - upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8531 - debian: conflated into https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860767 - debian patch: 0011-Fix-KDC-kadmind-startup-on-some-IPv4-only-systems.patch

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-05 Thread Andreas Hasenack
I'm taking a look. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1677329 Title: libpam-winbind: unable to dlopen To manage notifications about this bug go to: https://bugs.launchpad

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-05 Thread Andreas Hasenack
Where it works: 2:4.3.11+dfsg-0ubuntu0.14.04.7 trusty 2:4.3.11+dfsg-0ubuntu0.16.04.6 xenial 2:4.4.5+dfsg-2ubuntu5.5 yakkety Where it fails with this dlopen error: 2:4.5.8+dfsg-0ubuntu0.17.04.1 zesty artful: probably fails as well, as it's the same package still (but I haven't tried) -- You rece

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-05 Thread Andreas Hasenack
The patch d/patches/fix-1584485.patch got reintroduced in 2:4.5.4+dfsg- 1ubuntu1 for zesty and it's what causes the problem. Previously introduced in https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg- 0ubuntu0.14.04.2 to fix said bug, it was quickly reverted in https://launchpad.net/ubuntu/

[Bug 1455818] Re: [SRU] mysql-server-5.6.postrm fails when /usr/share/mysql-common/configure-symlinks doesn't exist

2017-05-05 Thread Andreas Hasenack
Yakkety now has mysql 5.7.18-0ubuntu0.16.10.1 in yakkety-updates. I tried a quick release-upgrade from up-to-date xenial which has 5.7.18-0ubuntu0.16.04.1 and it worked, no package installation errors. -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-08 Thread Andreas Hasenack
$ dpkg-shlibdeps -v debian/libpam-winbind/lib/x86_64-linux-gnu/security/pam_winbind.so >> Scanning debian/libpam-winbind/lib/x86_64-linux-gnu/security/pam_winbind.so >> (for Depends field) Library libpthread.so.0 found in /lib/x86_64-linux-gnu/libpthread.so.0 Library libbsd.so.0 found in /lib/x86

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-08 Thread Andreas Hasenack
I just did a test build with this and pam_winbind worked for the super simple login test case: http://pastebin.ubuntu.com/24536839/ diff -Nru samba-4.5.8+dfsg/debian/patches/fix-1584485.patch samba-4.5.8+dfsg/debian/patches/fix-1584485.patch --- samba-4.5.8+dfsg/debian/patches/fix-1584485.patch

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-08 Thread Andreas Hasenack
And dpkg-shlibdeps is happy: http://pastebin.ubuntu.com/24536871/ ubuntu@andreas-zesty-samba-test:~/deb/samba/samba-4.5.8+dfsg⟫ dpkg-shlibdeps -v debian/libpam-winbind/lib/x86_64-linux-gnu/security/pam_winbind.so >> Scanning debian/libpam-winbind/lib/x86_64-linux-gnu/security/pam_winbind.so >> (f

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-08 Thread Andreas Hasenack
** Changed in: samba (Ubuntu) Status: Confirmed => In Progress ** Changed in: samba (Ubuntu) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: samba (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-08 Thread Andreas Hasenack
** Changed in: samba (Ubuntu Zesty) Status: New => In Progress ** Changed in: samba (Ubuntu Zesty) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: samba (Ubuntu Zesty) Importance: Undecided => High -- You received this bug notification because

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-08 Thread Andreas Hasenack
A quick pam_winbind authentication test worked with that modification to the patch: http://pastebin.ubuntu.com/24539032/ May 8 21:13:25 zesty-pamwinbind-1677329 sshd[1221]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.0.100.1 user=BUGTEST\andreas

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-08 Thread Andreas Hasenack
** Tags added: patch -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1677329 Title: libpam-winbind: unable to dlopen To manage notifications about this bug go to: https://bugs.launchpa

[Bug 1455818] Re: [SRU] mysql-server-5.6.postrm fails when /usr/share/mysql-common/configure-symlinks doesn't exist

2017-05-09 Thread Andreas Hasenack
** Changed in: mysql-5.7 (Ubuntu) Status: Confirmed => Incomplete ** Changed in: mysql-5.7 (Ubuntu Xenial) Status: Confirmed => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launc

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-09 Thread Andreas Hasenack
This is a packaging merge proposal, you should use something like "dpkg- buildpackage -uc -us -b". If you just run ./configure and make in this branch you won't even get the debian patches applied. Unless I misunderstood your goal here, sorry. -- You received this bug notification because you are

[Bug 1669193] Re: feature request - json stats output

2017-05-11 Thread Andreas Hasenack
** Changed in: bind9 (Ubuntu) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: bind9 (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report.

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-11 Thread Andreas Hasenack
Thanks for your test, @jmurchik! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1677329 Title: libpam-winbind: unable to dlopen To manage notifications about this bug go to: https://b

[Bug 1574911] Re: vsftpd 500 oops stack smashing detected - Ubuntu 16.04

2017-05-11 Thread Andreas Hasenack
I posted some debugging in https://bugs.launchpad.net/ubuntu/+source /pam-mysql/+bug/1574900/comments/27 TL;DR - pam_mysql.c buf in pam_mysql_check_passwd() is overflowing - my_make_scrambled_password() is NOT returning content that can be compared to what is stored in the mysql DB when using PAS

Re: [Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-13 Thread Andreas Hasenack
You have to apply all the patches from the Debian package. I suggest to get the git branch and do a dpkg-buildpackage -uc -us -b On May 13, 2017 11:25, "Jason Lynn" wrote: > Also, should the symlink to /lib/x86_64-linux-gnu/security still be > required after this? > > -- > You received this bug

[Bug 1690270] Re: enable-esm should also install ca-certificates

2017-05-15 Thread Andreas Hasenack
Sorry, dependency* -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1690270 Title: enable-esm should also install ca-certificates To manage notifications about this bu

[Bug 1690270] Re: enable-esm should also install ca-certificates

2017-05-15 Thread Andreas Hasenack
Shouldn't apt-transport-https have a dependenci on ca-certificates? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1690270 Title: enable-esm should also install ca-ce

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-15 Thread Andreas Hasenack
On it. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs/1688121 Title: KDC/kadmind explicit wildcard listener addresses do not use pktinfo To manage notifications about this bug go to:

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-15 Thread Andreas Hasenack
** Description changed: This is fixed in artful in krb5 1.15-2 - upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8530 - debian: conflated into https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860767 - debian patch in artful's krb5: 0012-Use-pktinfo-for-explicit-UDP-wildcard

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-15 Thread Andreas Hasenack
** Description changed: This is fixed in artful in krb5 1.15-2 - upstream: http://krbdev.mit.edu/rt/Ticket/Display.html?id=8530 - debian: conflated into https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860767 - debian patch in artful's krb5: 0012-Use-pktinfo-for-explicit-UDP-wildcard

[Bug 1688121] Re: KDC/kadmind explicit wildcard listener addresses do not use pktinfo

2017-05-15 Thread Andreas Hasenack
I updated the test case with step (b.1) which I had forgotten. Here it goes: Reproducing the error case with 1.15-1, we can see that UDP is tried first, is ignored, and then TCP is used one second later: $ apt-cache policy krb5-kdc krb5-kdc: Installed: 1.15-1 Candidate: 1.15-1 Version table

[Bug 1688310] Re: KDC/kadmind may fail to start on IPv4-only systems

2017-05-15 Thread Andreas Hasenack
Reproducing the problem with 1.15-1: ubuntu@15-89:~$ apt-cache policy krb5-kdc krb5-kdc: Installed: 1.15-1 Candidate: 1.15-1 Version table: *** 1.15-1 500 500 http://br.archive.ubuntu.com/ubuntu zesty/universe amd64 Packages 100 /var/lib/dpkg/status After rebooting with no I

[Bug 1574911] Re: vsftpd 500 oops stack smashing detected - Ubuntu 16.04

2017-05-15 Thread Andreas Hasenack
pure-ftpd sorted this out by reimplementing make_scrambled_password() if it's not exported: https://github.com/jedisct1/pure- ftpd/commit/2db6b50c7b7c638104bd9639994f0574e8f4813c I don't know when make_scrambled_password() stopped being exported in libmysqlclient, but libmysqlclient's my_make_s

[Bug 1574911] Re: vsftpd 500 oops stack smashing detected - Ubuntu 16.04

2017-05-15 Thread Andreas Hasenack
** Changed in: pam-mysql (Ubuntu) Status: New => Confirmed ** Changed in: vsftpd (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/157491

[Bug 1574911] Re: vsftpd 500 oops stack smashing detected - Ubuntu 16.04

2017-05-15 Thread Andreas Hasenack
Submitted an issue against one of the forks of pam_mysql: https://github.com/NigelCunningham/pam-MySQL/issues/29 ** Bug watch added: github.com/NigelCunningham/pam-MySQL/issues #29 https://github.com/NigelCunningham/pam-MySQL/issues/29 -- You received this bug notification because you are a m

[Bug 1574911] Re: vsftpd 500 oops stack smashing detected - Ubuntu 16.04

2017-05-15 Thread Andreas Hasenack
Also submitted an issue against pure-ftpd, because it suffers from the same problem: https://github.com/jedisct1/pure-ftpd/issues/58 ** Bug watch added: github.com/jedisct1/pure-ftpd/issues #58 https://github.com/jedisct1/pure-ftpd/issues/58 -- You received this bug notification because you a

[Bug 1574911] Re: vsftpd 500 oops stack smashing detected - Ubuntu 16.04

2017-05-15 Thread Andreas Hasenack
pure-ftpd just fixed it: https://github.com/jedisct1/pure- ftpd/commit/27443b29320d85352d8b52c0120836843e10c0f9 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1574911 Title: vsftpd 500

Re: [Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-16 Thread Andreas Hasenack
I can upload the packages to a ppa for you to take a look On Tue, May 16, 2017 at 9:20 AM, Jason Lynn wrote: > Thanks. I was able to finally get it to build but after installing, the > samba service will no longer start. It simply times out and leaves > nothing the the syslog or the Samba log

[Bug 1574911] Re: my_make_scrambled_password() is not a replacement for make_scrambled_password()

2017-05-16 Thread Andreas Hasenack
** Summary changed: - vsftpd 500 oops stack smashing detected - Ubuntu 16.04 + my_make_scrambled_password() is not a replacement for make_scrambled_password() -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bug

[Bug 1574911] Re: my_make_scrambled_password() is not a replacement for make_scrambled_password()

2017-05-16 Thread Andreas Hasenack
** Description changed: - Ubuntu 16.04 x64 and Ubuntu 16.04 x86 - VSFTPD Version: vsftpd_3.0.3-3ubuntu2.debian + artful libpam-mysql-0.8.0-1 - When trying to use a fixed version of libpam-mysql (the one's I patched - here: https://bugs.launchpad.net/ubuntu/+source/pam-mysql/+bug/1574900) - wi

[Bug 1574911] Re: my_make_scrambled_password() is not a replacement for make_scrambled_password()

2017-05-16 Thread Andreas Hasenack
** Description changed: artful libpam-mysql-0.8.0-1 pam_mysql, when crypt=2 is set in its configuration, it expects the password to be hashed according to the server-side PASSWORD() SQL function. From its README: 2 (or "mysql") = Use MySQL PASSWORD() function. It is possible that t

[Bug 1574911] Re: my_make_scrambled_password() is not a replacement for make_scrambled_password()

2017-05-16 Thread Andreas Hasenack
Debian stretch isn't affected. There, libmariadbclient.so.18 exports a my_make_scrambled_password() that produces the correct/expected hexified hash. Which I wonder if it's what libmysqlclient.so.18 did (artful is at .20). -- You received this bug notification because you are a member of Ubuntu S

[Bug 1677329] Re: libpam-winbind: unable to dlopen

2017-05-17 Thread Andreas Hasenack
They are building, you can check progress here: https://launchpad.net/~ahasenack/+archive/ubuntu/samba-1677329/+packages samba is a big package, I bet it will take a few hours to build and publish. -- You received this bug notification because you are a member of Ubuntu Server Team, which is sub

[Bug 1574911] Re: my_make_scrambled_password() is not a replacement for make_scrambled_password()

2017-05-17 Thread Andreas Hasenack
Opened upstream bug against mysql explaining the situation. https://bugs.mysql.com/bug.php?id=86357 ** Bug watch added: MySQL Bug System #86357 http://bugs.mysql.com/bug.php?id=86357 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to

[Bug 1691826] Re: systemd script for sshd allows it to start too early should wait for authentication services...

2017-05-19 Thread Andreas Hasenack
Can you share your nss_ldap configuration, as well as /var/log/syslog and /var/log/auth.log? And, just to confirm, your sshd user is NOT in ldap, right? ** Changed in: cloud-init (Ubuntu) Status: New => Incomplete ** Changed in: openssh (Ubuntu) Status: New => Incomplete -- You re

[Bug 1692753] Re: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.6 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2017-05-23 Thread Andreas Hasenack
I can't find the failure reason in the attached logs. Could you please attach /var/log/samba/log.smbd? ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. http

[Bug 1692968] Re: ldb: unable to stat module ...

2017-05-23 Thread Andreas Hasenack
I'm taking a look at this. ** Changed in: samba (Ubuntu) Assignee: (unassigned) => Andreas Hasenack (ahasenack) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/169296

[Bug 1610361] Re: /usr/bin/deb-systemd-helper: error: systemctl preset failed on samba-ad-dc.service: No such file or directory

2017-05-23 Thread Andreas Hasenack
Debian's workaround: https://anonscm.debian.org/cgit/pkg- samba/samba.git/commit/?id=61eaeba2a7a2df61b681b4ea545811569de421d0 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1610361 Title

[Bug 1692968] Re: ldb: unable to stat module ...

2017-05-23 Thread Andreas Hasenack
Have you disabled install-recommends? Because samba-dsdb-modules is in the Recommends list for the samba package: root@zesty-samba-1692968:~# apt-cache show samba|grep Recommends Recommends: attr, logrotate, samba-dsdb-modules, samba-vfs-modules Recommends: attr, logrotate, samba-dsdb-modules, sam

[Bug 1692968] Re: ldb: unable to stat module ...

2017-05-23 Thread Andreas Hasenack
Can you install samba-dsdb-modules? That being said, even without that package, joining the domain worked: root@zesty-samba-1692968:~# l /usr/lib/x86_64-linux-gnu/samba/ldb ls: cannot access '/usr/lib/x86_64-linux-gnu/samba/ldb': No such file or directory root@zesty-samba-1692968:~# kinit Admin

[Bug 1693288] Re: package krb5-locales 1.15-1 failed to install/upgrade: El paquete está en un estado grave de inconsistencia - debe reinstalarlo antes de intentar su configuración.

2017-05-24 Thread Andreas Hasenack
krb5 had a failed upgrade on May 22nd: Start-Date: 2017-05-22 22:46:09 Commandline: aptdaemon role='role-upgrade-packages' sender=':1.122' Upgrade: krb5-locales:amd64 (1.15-1, 1.15-1ubuntu0.1), apport:amd64 (2.20.4-0ubuntu4, 2.20.4-0ubuntu4.1), python3-apport:amd64 (2.20.4-0ubuntu4, 2.20.4-0ubu

[Bug 1687449] Re: package samba 2:4.5.8+dfsg-0ubuntu0.17.04.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2017-05-24 Thread Andreas Hasenack
*** This bug is a duplicate of bug 1610361 *** https://bugs.launchpad.net/bugs/1610361 ** This bug has been marked a duplicate of bug 1610361 /usr/bin/deb-systemd-helper: error: systemctl preset failed on samba-ad-dc.service: No such file or directory -- You received this bug notificatio

[Bug 1610361] Re: /usr/bin/deb-systemd-helper: error: systemctl preset failed on samba-ad-dc.service: No such file or directory

2017-05-24 Thread Andreas Hasenack
I tried several combinations of fresh installs and upgrades. The "error" is always there, but doesn't translate to an exit status different than zero. In fact, debian and artful (synced from debian) now workaround the error by basically asking the admin to ignore it (https://anonscm.debian.org/cgit

[Bug 1573181] Re: Samba crashes wit "signal 11" error

2017-05-24 Thread Andreas Hasenack
@sombrafam, can you attach your smb.conf and the core file(s) from /var/log/samba/cores/smbd please? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1573181 Title: Samba crashes wit "s

[Bug 1573181] Re: Samba crashes wit "signal 11" error

2017-05-24 Thread Andreas Hasenack
Actually, ignore that. Could you please file a new bug instead with that info? You can use "apport-bug samba" IIRC. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1573181 Title: Samba

[Bug 1690684] Re: samba panic

2017-05-24 Thread Andreas Hasenack
> Now when I reboot I get the panic email. Is it always a new email about a new panic, or could it be that you are getting the same email over and over? Just checking. > Would you like the config file? yes, and the logs from /var/log/samba/ and any core files you might have in there. -- You re

[Bug 1693288] Re: package krb5-locales 1.15-1 failed to install/upgrade: El paquete está en un estado grave de inconsistencia - debe reinstalarlo antes de intentar su configuración.

2017-05-24 Thread Andreas Hasenack
Sorry, what you pasted doesn't contain entries for 2017-05-22, just 2017-05-18. Aren't there other files in /var/log/apt? Look for term.log* We need one of those that has entries for 2017-05-22. It will probably say something like "Log started: 2017-05-22 22:46:09" or close to that time. -- You r

[Bug 1693288] Re: package krb5-locales 1.15-1 failed to install/upgrade: El paquete está en un estado grave de inconsistencia - debe reinstalarlo antes de intentar su configuración.

2017-05-25 Thread Andreas Hasenack
We can't know for sure what happened then. I suspect a full disk, as you said you said in comment #3 that you had just 130MB available. I suggest for you now to run "sudo apt -f install" -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to

  1   2   3   4   5   6   7   8   9   10   >